defirisk.co
rubric v1.7.0

Sudden admin-rescue/ACL change without discussion

Across Protocol's assessment for RD-F-123 — scored gray on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Sudden admin-rescue / ACL change absent issue/PR discussion | The February 2, 2026 Ethereum SpokePool V2 upgrade (tx 0xce91ef569315a356ecbf8133df44de6a7f0cbbcc8f50433eb3ab5116d71a111f, block 24370830, new impl 0x5E5B726C81f43b953a62ad87e2835c85c4d9dd3b) was executed by the Hub Pool Owner MultiSig via `execTransaction`. The calling address in the Etherscan trace is the Risk Labs deployer initiating the exec on the Safe — confirming that execution went through the 3-of-5 Council multisig, not u...

Sources #

Methodology #

Determine whether any admin-rescue function or ACL change was committed to the repo or executed on-chain without corresponding public discussion in issues, PRs, or governance forum.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol across-protocol factor RD-F-123 score gray collected_at 2026-04-30 21:19:18